CVE-2026-5535 is a path traversal vulnerability found in FedML-AI FedML versions up to 0.8.9, specifically within the MQTT Message Handler's FileUtils.java component. Rated as Medium severity (CVSS 4.3), this flaw allows a remote attacker with low privileges to achieve limited confidentiality impact by manipulating the 'dataSet' argument. An exploit for this vulnerability has been publicly released, and it is listed on a hot list, indicating a high potential for active exploitation. The vendor has not responded to disclosure attempts, and despite minimal community discussion, the public exploit significantly increases the immediate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.9CPE matchmatch criteria | cpe:2.3:a:tensoropera:fedml:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.